OCR Provides Ransomware Resources

On September 21, the HHS Office for Civil Rights pushed out through their Listserv, a list of information to ensure that “HIPAA regulated entities are aware of the resources available to assist in preventing, detecting, and mitigating breaches of unsecured protected health information caused by hacking and ransomware.” Depending on the size of the organization and internal resources, some may handle theses critical issues in house. If this support is contracted to a managed service provider, your organization may want to make this information available to them.

Healthcare data is a prime target for bad actor. Organizations must be pro-active in fighting cybersecurity threats, whether handled in house or contracted out as a service. The HIPAA regulations require a contingency plan be in place, regardless of the size of the organization in case ePHI data is compromised.

Here is the list of those resources:

HHS Health Sector Cybersecurity Coordination Center Threat Briefs:

ยท https://www.hhs.gov/about/agencies/asa/ocio/hc3/products/index.html#sector-alerts

HHS Resources on Section 405(d) of the Cybersecurity Act of 2015:

OCR Guidance:

CISA Protecting Sensitive and Personal Information from Ransomware-Caused Data Breaches:

CISA Ransomware Guide:

FBI Ransomware Resources:

OCR Cybersecurity Newsletters:

REMINDER: A ransomware attack may result in a breach of unsecured protected health information that triggers reporting requirements under the HIPAA Breach Notification Rule. HIPAA covered entities and business associates should review OCRโ€™s ransomware guidance at https://www.hhs.gov/sites/default/files/RansomwareFactSheet.pdffor information regarding potential breach notification obligations following a ransomware attack.

At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.